Offensive Security

Penetration testing that proves what an attacker could reach.

A scanner tells you a port is open. CyNtell's testers tell you they went through that port, crossed three systems, and reached the share where your CUI lives, then hand you the evidence. Fixed fee, scoped to your environment, no surprise hourly overruns.

Authorized C3PAO SBA 8(a) · HUBZone GSA Schedule

What CyNtell tests

Seven disciplines, scoped to your environment

  • External and internal networks
  • Web, mobile, and SaaS applications
  • Microsoft 365 and GCC High tenants
  • Wireless, physical, and social engineering
3–5 weeks, scoping to final report
NIST SP 800-115 methodology
Last reviewed 7 September 2026
Reviewed by [NAME, CREDENTIALS]
Service area Washington, DC area, clients nationwide
Reading time 13 minutes
The Cyber AB Authorized C3PAO badge, CyNtell Authorized C3PAO
SBA 8(a) Certified badge, CyNtell SBA 8(a) Certified
SBA HUBZone Certified badge, CyNtell HUBZone Certified
GSA Schedule holder mark, CyNtell GSA Schedule Holder

Start here

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is automated and unverified. A penetration test is performed by a person who actually attempts the intrusion. A scan checks your systems against a database of known flaws and reports what it finds, including things that are not genuinely exploitable. A penetration test confirms what is real by exploiting it, chains findings together the way an attacker would, and documents the path with evidence.

Two related terms complete the set. A vulnerability assessment is a scan plus human analysis, with false positives removed and findings ranked by business risk, but no exploitation. A red team engagement is a goal-driven adversary simulation that tests whether your organization would detect an intrusion at all, rather than cataloguing what is exploitable. These four get sold interchangeably, and buying the wrong one is the most common way organizations spend real money and still fail the requirement they were trying to satisfy.

Penetration testing at CyNtell, the short version

What it is
An authorized, simulated attack in which a qualified tester attempts to defeat a system's security controls and documents how far an intruder could actually get.
What CyNtell tests
External and internal networks, wireless, web and mobile applications, SaaS platforms, Microsoft 365 and GCC High tenants, physical facilities, and social engineering, plus recurring vulnerability scanning as a subscription.
How it is priced
A fixed fee, scoped to the size of the environment. CyNtell does not bill hourly against an open estimate.
Methodology
NIST SP 800-115, the OWASP Web Security Testing Guide v4.2, and MITRE ATT&CK.
Who performs it
CyNtell personnel based in the United States.
Typical duration
Three to five weeks from scoping to final report, depending on scope.
Who CyNtell is
CyNtelligent Solutions LLC, trading as CyNtell, an Authorized CMMC Third Party Assessment Organization (C3PAO), SBA 8(a) and HUBZone certified, GSA Schedule holder, headquartered in the Washington, DC area and serving clients nationwide.

Start here

Scan, assessment, penetration test, red team: what is the difference?

These four get sold interchangeably. Here is what actually happens in each, what it proves, and how long it takes.

Service What actually happens What it proves Typical duration
Vulnerability scan An automated tool checks your systems against a database of known flaws and reports what it finds. What might be exploitable. Includes false positives. Nothing is verified. Hours
Vulnerability assessment The scan, plus a person who removes the false positives, adds what tools cannot see, and ranks findings by risk to your business. A trustworthy, prioritized list. Still no exploitation. Days
Penetration test A tester with written authorization attempts to break in, chains weaknesses together the way an attacker would, and documents the path. What a real intrusion reaches, with evidence. Not "this port is open" but "we reached your CUI file share, here is how." 1 to 3 weeks
Red team A goal-driven simulation to obtain a specific objective without being detected, by any realistic route, usually unannounced to your defenders. Whether you would notice. Tests detection and response, not just defenses. Weeks

The honest framing most vendors skip

A penetration test is time-boxed and scope-bound. It proves what was exploitable in a defined window against a defined set of systems. It is not a guarantee, and no framework treats it as one. Anyone selling it as a clean bill of health is selling you something else.

Scope

What does a penetration test cover?

CyNtell offers seven penetration testing disciplines plus a recurring vulnerability scanning program. Most engagements combine two or three, an external network test with a web application test, or a Microsoft 365 assessment with phishing simulation. CyNtell scopes what your environment and your compliance obligations actually call for rather than selling a fixed package.

01

Network penetration testing, external and internal

External testing works from the public internet inward: what an attacker sees with no credentials and no access. Internal testing starts from an assumed breach, a compromised laptop or a contractor's account, and answers the question that decides how bad a breach gets: once someone is inside, how far can they move, and what do they reach? For defense contractors that second answer is the one that matters, because it establishes whether a foothold anywhere becomes access to CUI.

Evidence for RA.L2-3.11.1 · CA.L2-3.12.1 · PCI DSS 11.4.2 / 11.4.3 · CIS 18.2 / 18.5

02

Wireless penetration testing

CyNtell wireless penetration testing checks whether your wireless perimeter, which extends into the parking lot, actually holds. CyNtell tests authentication and encryption on corporate and guest networks, looks for rogue and mis-scoped access points, and checks whether guest wireless is genuinely segmented from the network that handles regulated data, or only labelled that way. Segmentation that exists on the diagram but not in the switch configuration is one of the most common findings CyNtell reports.

Relevant to CUI enclave boundary validation and PCI DSS segmentation testing 11.4.5

03

Web and mobile application testing

Applications are the front door most attackers try first. CyNtell tests against the OWASP Web Security Testing Guide: authentication and session handling, access control between user roles, injection, business logic that can be driven somewhere it was never meant to go, and API endpoints that enforce less than the interface in front of them. Mobile applications are tested against the OWASP Mobile Application Security Testing Guide, including what the app stores on the device.

Methodology: OWASP WSTG v4.2 · OWASP MASTG / MASVS · supports PCI DSS 11.4.1 application-layer testing

04

SaaS platform assessment

You cannot penetration test a vendor's platform, their terms forbid it and it is not your system to test. What you can and should assess is your tenant: how it is configured, who has access, what integrations and OAuth grants are connected, how data leaves, and whether an offboarded employee's access truly ended. In most organizations the SaaS estate has grown faster than anyone's ability to inventory it, and third-party app grants are where CyNtell finds the quiet standing access nobody remembers approving.

Supports AC.L2-3.1.1 access control and 3.1.2 transaction limits · SOC 2 CC6.1 · ISO 27001 A.8.8

05

Microsoft 365 and GCC High assessment

Almost every defense contractor's CUI passes through Microsoft 365, and almost nobody assesses the tenant itself. CyNtell reviews Entra ID conditional access and privileged roles, Exchange Online mail flow and external forwarding, SharePoint and OneDrive sharing defaults, Teams external access, Intune device compliance, and audit logging, then checks the boundary that actually matters for compliance: whether CUI is confined to the environment you claim it lives in, or has quietly spilled into a commercial tenant that was never in scope.

Directly supports the CUI boundary claim in your SSP · SC.L2-3.13.1 boundary protection · AU.L2-3.3.1 audit logging

06

Physical security testing

CyNtell physical security testing establishes whether someone can simply walk in. Digital controls do not help if they can. CyNtell tests entry controls, badge and visitor procedures, reception and tailgating resistance, server room and wiring closet access, clean-desk practice, and the disposal path for media and printed material. For contractors with a physical CUI handling requirement, this is where the paper copy of the thing you spent a year protecting electronically tends to be found.

Evidence for the PE (Physical Protection) family · MP.L2-3.8.3 media sanitization

07

Social engineering and phishing simulation

Phishing simulation sent to your workforce, built to look like mail your people would plausibly receive, not the obvious template everyone already knows to report. CyNtell measures who clicked, who submitted credentials, who reported it, and how quickly, then turns that into targeted training rather than a shaming exercise. Pretexting by phone is available in scope where you want it. Reporting rate matters more than click rate: an organization where people raise their hand fast is one that survives the campaign that eventually works.

Supports AT.L2-3.2.1 / 3.2.2 awareness training · CIS 14.x · pairs with CyNtell security awareness training

08

Recurring vulnerability scanning

A penetration test is a point in time. The requirement most organizations actually carry is continuous: scan on a defined schedule, scan again when new vulnerabilities are published, and remediate on a risk basis. CyNtell runs that program as a subscription, authenticated and unauthenticated scanning against your defined schedule, findings triaged by a human so you get a real queue rather than raw tool output, remediation tracking, and a periodic evidence artifact written to be handed straight to an assessor or auditor.

This is the requirement itself: RA.L2-3.11.2 scan · RA.L2-3.11.3 remediate · GLBA 16 CFR 314.4(d) six-month cadence · PCI DSS 11.3

Method

How does CyNtell perform a penetration test?

CyNtell engagements follow the four-phase model in NIST SP 800-115: planning, discovery, attack, and reporting. That is the federal technical guide to security testing, the standard a government customer recognizes, and one that almost no commercial penetration testing vendor cites. Web application work follows the OWASP Web Security Testing Guide v4.2. Adversary behavior is described using MITRE ATT&CK, so findings map to techniques your SOC and your threat-hunting obligations already use, and the engagement phase model draws on PTES.

Security assessments are conducted to determine how effectively an entity being assessed meets specific security objectives.

NIST SP 800-115, Technical Guide to Information Security Testing and Assessment
Phase 01

Planning

Scope, rules of engagement, written authorization, testing windows, emergency contacts, and stop-work conditions agreed in writing before anything is touched.

Phase 02

Discovery

Mapping what is actually exposed, often more than the asset inventory says. Enumeration, service and version identification, and analysis of what each finding could permit.

Phase 03

Attack

Verified exploitation within scope. CyNtell confirms what is real, chains findings into the paths an attacker would take, and establishes how far each one goes.

Phase 04

Reporting

Findings ranked by business risk with reproduction steps and evidence, an executive summary that a non-technical reader can act on, and remediation guidance.

Critical findings do not wait for the report

If CyNtell reaches something that puts you at immediate risk, or finds evidence that someone else was already there, testing stops and you are called the same day. That escalation path is written into the rules of engagement before testing starts.

Deliverables

What is in a CyNtell penetration test report?

A CyNtell penetration test report contains six components: an executive summary, technical findings, an attack path narrative, compliance mapping, a remediation debrief, and an attestation letter. It is not a scanner export with a cover page. Every finding has been verified by a person, which means you are not paying your engineers to chase false positives.

01

Executive summary

What CyNtell found, what it means in business terms, and what to do first. Written to be read by a board, a prime contractor, or a customer's security team.

02

Technical findings

Each with severity, affected systems, reproduction steps, evidence, and specific remediation guidance.

03

Attack path narrative

The chain CyNtell followed end to end, so you can see how three medium findings combined into one critical outcome.

04

Compliance mapping

Findings mapped to the control or requirement they affect, so the report drops directly into your SSP evidence and your POA&M rather than needing to be translated first.

05

Remediation debrief

A working session with your technical team, because a report nobody understands changes nothing.

06

Attestation letter

A summary letter suitable for sharing with a prime, a customer, or an auditor without disclosing your findings detail.

Requirements

Which compliance frameworks require a penetration test?

Penetration testing is genuinely mandatory under PCI DSS, the GLBA Safeguards Rule, NY DFS Part 500, FedRAMP, and CMMC Level 3. It is not required by NIST SP 800-171, CMMC Levels 1 and 2, HIPAA, SOC 2, or ISO 27001, those require or expect vulnerability scanning and periodic assessment instead. A lot of security marketing implies every framework mandates testing. Knowing which rules genuinely require a test is the difference between buying what you need and buying what you were sold.

Annual penetration testing of your information systems determined each given year based on relevant identified risks in accordance with the risk assessment.

FTC Safeguards Rule, 16 CFR 314.4(d)(2)(i)
Framework Pen test required? Required frequency Citation
NIST SP 800-171 No, scanning only Scan "periodically" and when new vulnerabilities are identified 3.11.2 · 3.11.3
CMMC Level 1 No FAR 52.204-21
CMMC Level 2 No, scanning only Organization-defined scanning frequency RA.L2-3.11.2
CMMC Level 3 Yes At least annually, and on significant system change CA.L3-3.12.1e
PCI DSS v4.0.1 Yes Internal and external annually, plus after significant change; segmentation testing every 12 months, every 6 for service providers 11.4.2 · 11.4.3 · 11.4.5
GLBA Safeguards Rule Yes, conditionally Annual pen test plus vulnerability assessment every 6 months, unless you have effective continuous monitoring 16 CFR 314.4(d)
NY DFS Part 500 Yes Annually, from both inside and outside the system boundary 23 NYCRR 500.5(a)(1)
FedRAMP Yes Within 6 months of authorization package submission, then annually, across six defined attack vectors CA-8
HIPAA (current rule) No Requires risk analysis and periodic evaluation; a pen test is one accepted way to do it §164.308(a)(8)
SOC 2 Not required Named as a point of focus under CC4.1; most auditors expect an annual test as evidence CC4.1 · CC7.1
ISO 27001:2022 Not required Certification bodies commonly expect periodic testing as evidence A.8.8 · A.8.29
CIS Controls v8.1 Voluntary framework External annually at IG2 and above; internal annually at IG3. No obligation at IG1. Control 18

Worth knowing if you handle PHI

The HHS proposed Security Rule update would require penetration testing every 12 months and vulnerability scanning every 6. That rule is not final, drew more than four thousand comments, and is now targeted for 2027, so it is something to plan for, not something you are behind on.

For defense contractors

Does CMMC require a penetration test?

CMMC Level 2 does not require a penetration test. CMMC Level 3 does, at least annually. That is the whole answer; the detail is below.

At Level 2, no.

The phrase "penetration testing" does not appear anywhere in the CMMC Assessment Guide for Level 2, version 2.13. Level 2 is the 110 requirements of NIST SP 800-171 Revision 2, and those require you to scan for vulnerabilities, remediate them on a risk basis, and periodically assess whether your controls work. A C3PAO cannot mark you down for not having a penetration test. Any vendor telling you otherwise is either mistaken or selling.

Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified.

NIST SP 800-171 Rev. 2, requirement 3.11.2, the actual CMMC Level 2 obligation

At Level 3, yes, explicitly.

Level 3 draws on NIST SP 800-172, and CA.L3-3.12.1e requires penetration testing at least annually or when significant changes are made to the system. RA.L3-3.11.2e adds ongoing threat hunting. The levels and their source publications are set out in 32 CFR 170.14. If Level 3 is in your future, an annual test is not optional.

So why would a Level 2 contractor buy one?

Because CA.L2-3.12.1 requires you to assess whether your controls are actually effective, and a penetration test is the most defensible way to demonstrate that, far stronger than a scanner report and a signature. Because findings feed RA.L2-3.11.1, your risk assessment. And because the most expensive place to discover that your CUI boundary does not hold is in front of an assessor, not before one.

Where CMMC stands right now

On 13 July 2026 the Department of War (DoW) suspended CMMC Phase 2, halting the third-party certification tier that was to begin in November 2026 and directing contracting officers to remove C3PAO and DIBCAC assessment requirements from active solicitations pending a 60-day review.

What did not change:

DFARS 252.204-7012 remains in effect, including the 72-hour cyber incident reporting obligation. DFARS 252.204-7019 and 7020 still require your SPRS self-assessment score. NIST SP 800-171 Revision 2 remains the baseline, and 32 CFR Part 170 remains on the books. Level 1 and Level 2 self-assessment obligations are firmly in place, with the Level 2 self-assessment deadline at 1 March 2027. The suspension paused how the requirement is verified. It did not pause the requirement.

Independence

Can the same firm penetration test you and run your CMMC assessment?

Possibly not, and CyNtell will tell you which before you sign. It is a fair question to ask a company that is both an Authorized C3PAO and a security services provider, and most firms in this position simply do not address it.

Prohibit CMMC Ecosystem members from participating in the Level 2 certification assessment process for an assessment in which they previously served as a consultant to prepare the organization for any CMMC assessment within 3 years.

32 CFR 170.8(b)(17)(ii)(G)

C3PAOs are also required to operate under ISO/IEC 17020 as independent inspection bodies, which restricts providing services that would compromise impartiality.

In practice this means one thing for you: engaging CyNtell for penetration testing may affect CyNtell's eligibility to serve as your C3PAO assessor. CyNtell will tell you which side of that line an engagement falls on before you sign anything, not after. If you intend to use CyNtell as your assessor, CyNtell will say so and scope accordingly, and if the right answer is that another firm should do the testing, CyNtell will say that too.

Pricing

How much does a penetration test cost?

CyNtell prices penetration testing as a fixed fee, scoped to the size of what is being tested. You get the number before the work starts and it does not move unless the scope moves. CyNtell does not bill hourly against an open estimate, which is how testing engagements quietly become twice what was budgeted.

Scope, and therefore price, is driven by six things, all of which can be established in a short call:

01

External footprint

How many live public IP addresses and internet-facing hosts you have.

02

Internal environment

Number of sites, network segments, and endpoints in the tested boundary.

03

Applications

How many, how complex, and how many distinct user roles each has.

04

Cloud and SaaS

Which platforms are in scope and how many tenants.

05

People

Headcount in scope for phishing simulation.

06

Physical

Number of facilities to be tested.

Bring your last test's scope document or your SSP boundary diagram to the call and CyNtell can usually scope it in a single conversation.

Before testing begins

What authorization is required before a penetration test?

Written authorization from someone with authority over every system in scope, plus a documented rules-of-engagement package. Testing a system without it is a federal crime under the Computer Fraud and Abuse Act, 18 U.S.C. § 1030. Every CyNtell engagement begins with signed authorization and rules of engagement covering in-scope and explicitly out-of-scope systems, testing windows, prohibited techniques, data handling, and emergency stop-work contacts on both sides.

If you do not own an asset in scope, a leased data center, a managed platform, or a third party's infrastructure, the owner has to authorize it too. CyNtell will help you get that in place rather than testing around it.

Can you penetration test cloud environments?

Yes. AWS, Microsoft Azure, and Google Cloud all permit testing of your own resources without advance approval, but each prohibits denial-of-service testing and anything reaching outside your own tenancy. Microsoft 365 is the one people get wrong: it sits under the separate Microsoft Cloud Unified Penetration Testing Rules of Engagement, not the Azure policy, and third-party phishing sent at a live M365 tenant is not permitted. CyNtell runs M365 phishing simulation through Microsoft's own Attack Simulation Training.

Questions

Frequently asked questions

How long does a penetration test take?

A CyNtell penetration test takes three to five weeks from scoping to final report. Scoping and authorization usually take one to two weeks, active testing one to two weeks depending on scope, and reporting about a week. A single external network test can be considerably faster; a multi-site engagement with applications and physical testing takes longer.

What is the difference between a vulnerability scan and a penetration test?

A scan is automated and tells you what might be exploitable, including things that are not. A penetration test has a person verify it, actually attempting the intrusion and documenting how far it goes. Scanning answers "what looks wrong?" Testing answers "what can someone actually do?" Most compliance frameworks require scanning; fewer require testing. PCI DSS, the GLBA Safeguards Rule, NY DFS Part 500, FedRAMP, and CMMC Level 3 require penetration testing. NIST SP 800-171, CMMC Levels 1 and 2, HIPAA, SOC 2, and ISO 27001 do not.

Can a vulnerability scan satisfy a penetration testing requirement?

No. Where a framework requires penetration testing, CMMC Level 3, PCI DSS 11.4, FedRAMP, NY DFS, and the GLBA Safeguards Rule, a scan does not satisfy it. The reverse is also true: a penetration test does not replace your recurring scanning obligation under NIST SP 800-171 3.11.2, because that requirement is about ongoing frequency, not depth.

How often should we test?

Annually, plus after any significant change to your infrastructure or applications. That is the floor set by nearly every framework that requires testing at all. If you are subject to PCI DSS as a service provider, segmentation testing runs every six months. If your environment changes constantly, an annual test is a snapshot of a system that no longer exists, which is the case for a recurring scanning program alongside it.

Will testing disrupt our operations?

A CyNtell penetration test should not disrupt operations, and preventing it is what the rules of engagement are for. Denial-of-service and destructive techniques are excluded by default. Testing windows are agreed in advance around your operational calendar, and CyNtell holds a live contact on your side throughout with authority to call a stop. Fragile legacy systems get flagged during scoping and handled with agreed constraints rather than discovered the hard way.

Is penetration testing required for CMMC Level 2?

No. Level 2 requires vulnerability scanning under RA.L2-3.11.2 and periodic control assessment under CA.L2-3.12.1. Penetration testing is not named anywhere in the Level 2 assessment guide. It becomes a requirement at Level 3, under CA.L3-3.12.1e, where it is required at least annually.

Do penetration test findings have to go on our POA&M?

Penetration test findings that represent an unmet security requirement belong in your POA&M; findings that are risk observations without a mapped requirement do not. This is exactly why CyNtell reports map each finding to the control it affects, so the decision is documented and defensible rather than a judgment call someone makes later under pressure.

What do you need from us to scope an engagement?

CyNtell needs seven things to scope a penetration test: your external IP ranges and domains, a rough count of internal hosts and sites, a list of applications with their user roles, which cloud and SaaS platforms are in scope, headcount if phishing is included, and whichever compliance obligation is driving the work. If you have an SSP boundary diagram or a prior scope document, that usually covers all of it.

Are your testers based in the United States?

Yes, CyNtell penetration testing is performed by CyNtell personnel in the United States. For engagements touching CUI or covered defense information, that is not a preference, it is a requirement, and it is worth confirming with any provider you evaluate.

Sources

References cited on this page

Every regulatory claim above is linked to its primary source. If a requirement has changed since this page was last updated, the source governs.

  • NIST SP 800-171 Rev. 2requirements 3.11.1, 3.11.2, 3.11.3, 3.12.1
  • NIST SP 800-115Technical Guide to Information Security Testing and Assessment
  • CMMC Assessment Guide, Level 2 v2.13DoW CIO
  • 32 CFR Part 170the CMMC program rule, including §170.8 conflict of interest and §170.14 model levels
  • DFARS 252.204-7012safeguarding covered defense information and cyber incident reporting
  • 16 CFR 314.4FTC Safeguards Rule
  • 23 NYCRR 500.5NY DFS cybersecurity requirements
  • FedRAMP Penetration Test Guidance v3.0
  • HHS HIPAA Security Rule NPRM fact sheetproposed, not in force
  • OWASP Web Security Testing Guide · OWASP MASTG · MITRE ATT&CK
  • Microsoft Cloud Unified Penetration Testing Rules of Engagement · AWS · Google Cloud

A short scoping call, a fixed fee, a report your assessor will accept

Find out what an attacker would actually reach.

Bring your last test's scope document or your SSP boundary diagram. We will scope it in a single conversation, give you the number before the work starts, and hand your engineers a report they can act on. CyNtell is an Authorized C3PAO headquartered in the Washington, DC area, serving commercial and government clients nationwide.

Cyber AB Authorized C3PAO badge Cyber AB Registered Practitioner Organization RPO badge SBA 8a certified HUBZone certified HIPAA compliance verification seal

CyNtelligent Solutions, LLC (CyNtell), cybersecurity, compliance, and IT security operations for the federal government, the defense industrial base, and regulated industry.

Assessor independence. CyNtelligent Solutions, LLC (CyNtell) is an Authorized C3PAO, listed on the Cyber AB Marketplace. CMMC certification assessment work and consulting engagements are delivered by separate engagement teams, and never the same personnel on an assessment and the advisory work behind it. Consistent with Cyber AB conflict-of-interest requirements, CyNtell does not perform a certification assessment of an environment it has consulted on.